CVE-2026-56694

⚪ Do wiadomości

W NanoClaw występuje luka eskalacji uprawnień, umożliwiająca nieautoryzowany dostęp do grup agentów.

CVSS
5.4
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups. Scoped admins can submit forged or stale connect callback values to wire messaging channels into out-of-scope agent groups, exposing unauthorized groups to unapproved channels and enabling unauthorized observation or control of restricted agent group activity.

privilege-escalation Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.4
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-06-23 16:17:06 UTC
Ostatnia modyfikacja (NVD)2026-09-17 18:16:52 UTC
Referencje